Live data from Hacker News

Pegasus spyware found on journalists’ phones, French intelligence confirms

theguardian.com

81–90 of 101 posts

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#82

Is there no regulatory or compliance requirements for surveillance software? Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework aro…

I agree that laws are the right way to deal with this - there will always be another vulnerability for bad actors to exploit; technical solutions are not the answer unless you want to move your smartphone at the pace and rigor of the Apollo program - but I three real challenges here:

1. If NSO enjoy the tacit support of the Israeli government, then they are effectively judgement proof, no different to crimeware businesses that enjoy the tacit support of the Russian government.

2. Major Western governments such as the US will support the Israeli government for "bigger picture" reasons, and potentially implicitly the NSO. Particularly if the NSO are "only" facilitating the torture and murder of journalists who upset the Saudi government. So again, whatever national laws or international agreements may be in place don't really matter. Much as you'll never see a Blackwater mercenary in front of the war crimes tribunal in the Hague, you'll never see the NSO charged anywhere.

3. More broadly, there have been solid international frameworks for cracking down on, for example, money laundering. The AMLAT treaties are quite effective for money laundering, not so much for finance of terrorism. No nation outside of Canada has designated ISIS-like organisations as terrorists, subject to finance controls, for example. Trying to get an effective, multilateral agreement on how to handle tools that many governments want cheap access to in order to attack their enemies will be quite the challenge.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#83
post #51

Earlier quoted context omitted.

> Is there no regulatory or compliance requirements for surveillance software? Nope! It's not even clear if Pegasus and its employees broke any laws. (Though I would love to see CFAA and copyright law tested against this.) Optimistically, this might be the wake-up call to change that.

IANAL but lots of countries have laws against gaining access to computing devices or data without prior authorisation.

https://en.wikipedia.org/wiki/Aaron_Swartz#Arrest_and_prosec...

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#85
post #79

Earlier quoted context omitted.

No, but when they appear, _you can fix them_.

Are there actual hard numbers on whether open-to-all-eyes is beneficial at all scales? For example, do public eyes actually catch and did more Linux bugs than three letter agencies? And would this situation be worse if Linux were a very well funded, closed source Windows? I’m ignorant on whether the open source security mantra is founded upon religion or evidence.

Classical FUD.

> For example, do public eyes actually catch and did more Linux bugs than three letter agencies?

Is it so important, who found a bug? TLA can find a bug, and then it has a choice: TLA can use it to spy on other countries, or TLA can fix it to protect their own country.

Your TLA may choose to leave your country unprotected, but it is the problem of your country.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#86
post #28

" Bredoux added: “It takes a bit of time to realise it, but it’s extremely unpleasant to think that one is being spied on, that photos of your husband and children, your friends – who are all collateral victims – are being looked at; that there is no space in which you can escape. It’s very disturbing.” " Welcome to the future! It's pretty much the same as the past, only more effective.

I know Lenaïg since I’ve been working at Mediapart a few years ago. I feel sorry for her. We were very careful on all security aspects, and it’s sad to see it’s never enough.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#87
post #28

" Bredoux added: “It takes a bit of time to realise it, but it’s extremely unpleasant to think that one is being spied on, that photos of your husband and children, your friends – who are all collateral victims – are being looked at; that there is no space in which you can escape. It’s very disturbing.” " Welcome to the future! It's pretty much the same as the past, only more effective.

This is why we need competent people at EU level and national governments. The current leadership is very much in favor of such surveillance. In Germany, it is even large parts of the press, which is pretty damning given their profession.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#88
post #3
post #2

Ironically, users themselves are disallowed from rooting their phones. Right to root, is right to repair.

I'm all for having the right to repair. I'm not convinced any of the folks involved ability to root would prevent the situation described.

It would give you the ability to check at least. Not having root doesn't protect you evidently.

Smartphone landscape of software is a huge failure aside from monetization of apps and user data.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#89
post #58

Earlier quoted context omitted.

But if that imessage vulnerability was FOSS and you could flash your own image, you could fix it and move on with your life.

>But if that imessage vulnerability was FOSS and you could flash your own image 1. the vulnerability wasn't FOSS. It was kept under wraps because otherwise it would get discovered and apple would patch it 2. what makes you think that amateurs working in their free time can patch 0days faster than the vendors themselves?

Because these "amateurs" build all the essential tools we rely on today. That wasn't Apple. I cannot really believe what crap I have to read here. Vendor lock in is a huge factor for insecurity in software.

Re: Pegasus spyware found on journalists’ phones, French intelligence confirms

#90
post #74

Earlier quoted context omitted.

It's not yet even possibly to reliably detect the infection because of the closed nature of the device. I think I'd like to check my iPhone, but I can't reliably do that. So that, for a start, would help.

>I think I'd like to check my iPhone, but I can't reliably do that. but you can, via itunes backup.

Reading the dump? That isn't nearly as effective as giving users the ability to administer their system. That is in no way an alternative.
Post reply on HN